Ginwui

First seen
2010-12-12 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 14:43:53

Targeted industries: government-and-public-sector

Targeted regions: country_code:cn country_code:hk

Context

Ginwui is a remote access trojan (RAT) that targets government and public sector organizations. It is primarily used by threat actors associated with cyber espionage activities, particularly targeting entities in China and Hong Kong.

Reports & references

  • elastic.co — Ten Process Injection Techniques Technical Survey Common And Trending Process (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Ginwui (report)

External references